Skip to main content

Log File Events

Home > Select Project > Alert Icon Alert > Event Configuration > File keyword monitoring / Windows event monitoring / File monitoring tab

WhaTap Monitoring detects a wide range of anomalies that occur in log files and delivers alerts accordingly. When you configure event rules, you can receive alerts at either the Warning (Warning) or Critical (Critical) level whenever specified conditions are met. Log-based events are provided in three types.

  • File Keyword Monitoring
  • Windows Event Monitoring
  • File Monitoring
Caution

For file keyword monitoring, Windows event monitoring, and file monitoring, the recipient tag feature is supported only on agent version 2.4.6 or later.

Default Options

  • Search: Search for specific events by selecting an event name or an event recipient tag.
  • + Add Event Rule: Add a new event rule.
ItemDescription
ConditionLog conditions used for event detection (file path, search keyword, etc.)
ServerThe server to which the event condition applies
Event Recipient TagUser groups that will receive notifications
Edit IconEdit a saved event

Enabling and disabling event rules

You can enable or disable registered log file event rules individually without deleting them. When you disable a rule, its configuration is kept as is and only event detection stops. A newly added rule is active by default.

You can toggle enable/disable in two places. In the event list, toggle it with the switch on the right of each event rule item; in the event rule edit window, toggle it with the Enable toggle at the top right.

Add Event Rules

Manage specific log files and Windows event settings.

  1. Go to Alert Icon Alert > Event Configuration > File keyword monitoring / Windows event monitoring / File monitoring tab.

  2. Click the [ + Add Event Rule ] button.

  3. Enter an event name (up to 100 characters) in Title.

  4. Select servers from the Server List and click [ Apply ].

    a. When the Project Default Policy toggle is enabled, the default alert policy is applied to servers managed by the project.

  5. Select a Log Type (File Keyword Monitoring, Windows Event Monitoring, File Monitoring) under Event Trigger Conditions.

    File Keyword Monitoring
    ItemDescription
    File Path (Required)Enter the path of the file to monitor.
    - Date and time patterns can be used in file names.
    - Example: /var/log/mylogfile_%Y-%m-%d_%H:%M:%S.log
    Search KeywordEnter keywords to detect in the file.
    - Multiple keywords can be entered.
    - Example: keyword1|keyword2|keyword3
    Excluded StringsEnter strings to exclude from alerts.
    - Multiple strings can be entered.
    - Supported on agent version 1.2.7 or later
    - Example: keyword1|keyword2|keyword3
    Repeat (Count)Number of times the specified keyword must be detected
    Period (Seconds)Time window in which the repeat condition must be met
    SeverityAlert level triggered when conditions are met
    - Critical: Critical alert
    - Warning: Warning alert
    Windows Event Monitoring
    Note

    Available only in Windows environments.

    ItemDescription
    Log NameSelect the type of Windows event log to monitor
    - Application
    - Security
    - Setup
    - System
    - Forwarded Events
    LevelSelect the event level to monitor
    - Information
    - Warning
    - Critical, Error
    - Audit Success
    - Audit Failure
    SourceEnter the event source to monitor
    Event IDEnter the numeric event ID
    Search KeywordEnter keywords to detect in the log
    - Multiple keywords can be entered
    - Not applied to the keyword field in Windows Event Viewer
    - Example: keyword1|keyword2|keyword3
    Excluded StringsEnter strings to exclude from alerts
    - Multiple strings can be entered
    - Supported on agent version 1.2.7 or later
    - Example: keyword1|keyword2|keyword3
    Repeat (Count)Number of times the specified keyword must be detected
    Period (Seconds)Time window in which the repeat condition must be met
    SeverityAlert level triggered when conditions are met
    - Critical: Critical alert
    - Warning: Warning alert

    Log Throughput

    Log throughput is limited based on log lines. When logs are generated excessively in a short period, only up to the configured throughput is collected to prevent excessive agent CPU usage. Excess log lines are not processed.

    VersionThroughput (per 2 seconds)
    Version 1.3.6 or earlierApprox. 60 lines
    Version 1.3.7 or laterApprox. 100 lines

    You can control the excess amount per 2 seconds using the following options.

    • Linux: Set log.skip.threshold=number_of_lines_per_2_seconds in /usr/whatap/infra/conf/whatap.conf

    • Windows: Set log.skip.threshold=number_of_lines_per_2_seconds in C:\Program Files\WhatapInfra\whatap.conf

    File Monitoring
    Note

    Supported on Linux and Windows environments starting from agent version 2.9.4.

    Unix environments are not supported.

    ItemDescription
    File Path (Required)Enter the path of the file to monitor
    - Date and time patterns can be used in file names
    - Example: /var/log/mylogfile_%Y-%m-%d_%H:%M:%S.log
    Monitoring ItemSelect the file attribute to monitor
    - Owner Change: Alert when the file owner (user) changes (Not supported on Windows OS)
    - Group Change: Alert when the file group changes (Not supported on Windows OS)
    - Permission Change: Alert when file permissions change (Not supported on Windows OS)
    - File Deletion: Alert when the file is deleted
    - File Modified Time: Alert when the file’s last modified time changes
    SeverityAlert level triggered when conditions are met
    - Critical: Critical alert
    - Warning: Warning alert
  6. Click + Add Log Event Condition to add additional log event conditions.

  7. Click + Add to configure Event Active Time.

    Assign tags to define when events are active, such as working hours, non-working hours, or maintenance periods. If no tag is set, events remain active 24 hours a day.

    a. Click + Create New Tag under Event Active Time.

    b. In Create Event Active Time Tag, select a tag name, days, time, and color, then click [ Apply ].

    c. Created tags appear in the tag list and can be applied by selecting the checkbox.

    d. Click the edit icon Edit Icon to modify or delete tags in Edit Event Active Time Tag.

    Caution

    When a tag is deleted, it is removed from all users to whom it is applied. However, tags currently in use by event rules cannot be deleted.

  8. Click the [ + Add Tag ] button under Event Recipient Tags and select recipients from the tag list. You can also add a new tag by selecting + Create New Tag.

    • Selecting event recipient tags sends notifications to project members and third-party plugins associated with those tags. You can assign tags to project members and third-party plugins separately in the Event Notification Settings menu.
  9. Once log event configuration is complete, click [ Save ].

Edit Event

  1. Go to Alert Icon Alert > Event Configuration > File keyword monitoring / Windows event monitoring / File monitoring tab.

  2. Click the Edit icon icon for the event you want to edit.

  3. Modify the event in the Add Event Rule window.

  4. Click the [ Save ] button.

    • After the update, new alerts are triggered when incoming data meets the updated conditions.

Delete Event

  1. Go to Alert Icon Alert > Event Configuration > File keyword monitoring / Windows event monitoring / File monitoring tab.

  2. Click the Edit icon icon for the event you want to delete.

  3. In the Add Event Rule window, click the [ Delete ] button in the upper right corner.

Copy Event

Copy the selected event rules to one or more projects.

  1. Go to Alert Icon Alert > Event Configuration > File keyword monitoring / Windows event monitoring / File monitoring tab.

  2. Select one or more events to copy, then click Copy. The Copy Event window opens.

  3. Select the target projects to copy to. You can select multiple projects at once, including the current project, and only projects for which you have event configuration permission can be selected.

  4. If needed, specify Copy as active. Whether each copy is active can be set per event, and the default is inactive.

  5. Click Copy. The selected events are copied to each target project.

  • The copied event name gets a _Copy suffix. No number is appended, so repeated copies are created with the same name (Name_Copy).

Exporting and importing event settings as JSON

You can download all registered log file event rules as a JSON file and import rules from a JSON file. Use it to apply the same rules to another project or to back up the current settings. The JSON button is displayed only to users with event edit permission.

Exporting JSON

  1. Go to Alert Icon Alert > Event Configuration > File keyword monitoring / Windows event monitoring / File monitoring tab.

  2. Click the JSON button in the upper right. The Event Rules window displays all rules of the current project in JSON format. All rules are always retrieved regardless of the search conditions and event type filter specified on the screen.

  3. Click the Export button.

  4. In the confirmation window, choose whether to select Include target servers and recipient tags.

    • Clear the selection if the file is to be applied to another project. Target servers and recipient tags have different values in each project, so they do not match when transferred as is.

    • When the selection is cleared, the receiver, timeTag, and attachedOids values in the downloaded file are saved as empty arrays. This applies only to the file; the settings of the current project remain unchanged.

    • The option is reset to the included state each time the confirmation window opens.

  5. Click the Download button. A file named log-event-rules-{project code}-{export date}.json is downloaded.

If you edit the JSON directly in the Event Rules window and click the Save button, all rules of the current project are replaced with the edited content. Rules not in the list shown in the window are deleted, so do not save with only some of the rules left.

Importing JSON

  1. Go to Alert Icon Alert > Event Configuration > File keyword monitoring / Windows event monitoring / File monitoring tab.

  2. Click the import icon button next to the JSON button in the upper right, then select the JSON file to import.

  3. Check the imported content in the Event Rules window. If any item does not match the format, an error message appears at the bottom of the window, and you cannot save until the error is fixed. You can edit the content directly in the window.

  4. Click the Add to list or Overwrite button.

    • Add to list: adds the rules from the file while keeping the existing rules.

    • Overwrite: replaces all rules of the current project with the rules from the file. Existing rules that are not in the file are deleted.

The eventId of each rule is reissued with a new value when the file is read. This means a file downloaded from the same project can also be imported without identifier conflicts.

Validation conditions

The imported JSON is checked against the following conditions before it is saved. The top-level structure must be a JSON array containing one or more rules.

FieldTypeDescription
eventIdstringRule identifier. Cannot be empty or duplicated within the list
titlestringRule name
enabledbooleanWhether the rule is enabled
logDefaultbooleanWhether the rule applies to all servers
receiverarray<string>List of event recipient tags
timeTagarray<string>List of event active time tags
attachedOidsarray<number>List of target servers
conditionsarrayList of event conditions. At least one is required
FieldTypeDescription
eventSourcenumberEvent type. Only 1 (file keyword monitoring), 2 (Windows event monitoring), and 5 (file monitoring) are supported
filePathstringRequired when eventSource is 1 or 5
winLogFilestringRequired when eventSource is 2